The canonical Workspai security policy defines supported versions, private reporting channels, response expectations, coordinated disclosure, and safe research guidance:
Read the canonical security policy
Do not report a suspected vulnerability through a public issue, discussion, or pull request. Use a private GitHub security advisory or email security@workspai.dev.
When using Workspai:
- Keep Workspai and generated dependencies updated.
- Review generated source and configuration before deployment.
- Install official releases from the npm registry.
- Run the ecosystem-appropriate audit tools on generated projects.
- Treat executable configuration as code. Prefer
workspai.config.json; use--trust-configafter reviewing JavaScript configuration. - Keep remote archives public-network-only. Private and loopback archive
URLs are rejected unless
--allow-private-networkis explicitly supplied. - Keep mirror targets constrained. Artifact targets are restricted to the managed mirror directory and are committed only after integrity/policy verification.